


Perceptive Security
SOC/SIEM Consultancy

Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Toolbox\Resourc…
Published:
3 August 2026 at 00:00:00
Alert date:
3 August 2026 at 17:06:10
Source:
nvd.nist.gov
Web Technologies, Data Breach & Exfiltration
Grav CMS version 2.0.10 contains a path traversal vulnerability in the ImageMedium::watermark() method. The vulnerability arises because the unsanitized $image argument is passed to UniformResourceLocator::findResource() without proper containment checks. The file:// scheme branch only lexically collapses '..' segments, lacking a realpath or sandbox containment check. An authenticated editor can craft Markdown image syntax with traversal sequences to access arbitrary image files outside the media sandbox. These files are then composited into a carrier image, cached, and served from a public unauthenticated URL, leading to information disclosure. Multiple GitHub commits have been issued as fixes, along with a security advisory on GitHub and coverage from VulnCheck. The vulnerability represents a significant risk due to unauthenticated access to disclosed files.
Technical details
Mitigation steps:
Affected products:
Grav CMS 2.0.10
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69089
https://github.com/getgrav/grav/commit/b282200a65ce979377963180629babd2335212ba
https://github.com/getgrav/grav/commit/c569a53304cd7d95ff21bffa6fc590adcf0be83d
https://github.com/getgrav/grav/commit/db8c1fcd63aaaf6d6b244bc6b4cfa5f7b96bbc7f
https://github.com/getgrav/grav/security/advisories/GHSA-w3f4-8pj2-599w
https://www.vulncheck.com/advisories/grav-cms-before-path-traversal-via-watermark
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
